Microsoft Security Response Center guidance
Vendor revision: Aug 12, 2026Vendor remediation details
CBL-Mariner Releases
Vendor-listed releases
- 1.0.1-2
- 0.29.1-3
- 1.25-2
- 1.2.2-2
Vulnerability intelligence
CVE-2025-29481 and is rated Medium severity with a CVSS score of 6.2. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases
Vendor-listed releases
Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf. This has been disputed by third parties who assert that "no one in their sane mind should be passing untrusted ELF files into libbpf while running under root."
Source: NVD